OpenWrt discloses forum data breach

The OpenWrt challenge has revealed that an attacker has managed to entry details about its on-line forum customers over the weekend, by compromising the account of a forum administrator.
“The intruder was able to download a copy of the user list that contains email addresses, handles, and other statistical information about the users of the forum,” they shared.
“Although we do not believe the intruder could download the database, from an abundance of caution, we are following the advice of the Discourse community and have reset all passwords on the Forum, and flushed any API keys.”
What is OpenWrt?
The OpenWrt project oversees the event of OpenWrt, an open-source, Linux-based embedded working system/firmaware for a wide range of routers and gateways, which can be used on smartphones, laptops and private computer systems.
“People install OpenWrt because they believe it works better than the stock firmware from their vendor. They find it is more stable, offers more features, is more secure and has better support,” OpenWrt builders level out.
The challenge releases common bug fixes and safety updates – even for units that are actually unsupported by their authentic producers.
More concerning the OpenWRT data breach
The OpenWrt challenge mentioned that whereas the password of the compromised forum admin account was robust, the account was not moreover secured with 2-factor authentication.
They additionally assured customers that the OpenWRT Wiki, which homes information concerning the challenge, documentation and obtain hyperlinks, has not been compromised. The OpenWrt forum credentials are impartial of the OpenWrt Wiki, they mentioned, and “there is no reason to believe there has been any compromise to the Wiki credentials.”
The predominant fear is that the intruder could use the consumer record to ship out phishing emails geared toward compromising the accounts or methods of the forum’s common customers, a few of which work for firms that manufacture units and develop software program that may run (on) OpenWrt.
Forum customers have been suggested to be looking out for phishing emails and to entry the forum independently of a hyperlink in an e mail. They may also must reset their password and in the event that they use Github login/OAuth key, they need to reset/refresh it.
Source link


![The OpenWrt One system [LWN.net] The OpenWrt One system [LWN.net]](https://openwrtrouters.net/wp-content/uploads/2026/09/openwrt-one-sm-250x220.png)